text-to-speech

Fail

Audited by Socket on Mar 19, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core TTS capability is broadly consistent with the stated purpose, and the installer appears to be the publisher's documented same-org path with checksum verification, keeping malware likelihood low. The main concerns are the pipe-to-shell install, handing account auth to an external CLI, broad `infsh *` bash capability, and especially the explicit installation of additional skills via `npx skills add`, which extends trust transitively beyond this skill.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 19, 2026, 01:43 PM
Package URL
pkg:socket/skills-sh/inference-sh-8%2Fskills%2Ftext-to-speech%2F@45d7a73fbdfd55f3a24ca1f09e0e23082c24720b